team-brief

Warn

Audited by Socket on Mar 14, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is largely coherent with its stated purpose, and its network endpoints are official, but it has a broad and high-impact footprint. The main concerns are automatic write-back to Linear, reading a raw local token, and publishing aggregated internal intelligence to HackMD. This looks like an overpowered internal ops skill rather than malware, with medium security risk due to scope and outbound data flow.

Confidence: 88%Severity: 62%
Audit Metadata
Analyzed At
Mar 14, 2026, 11:31 AM
Package URL
pkg:socket/skills-sh/huytieu%2FCOG-second-brain%2Fteam-brief%2F@807ee02f9235db9adea5adf26c45e47dee9438e7
Security Audit — socket — team-brief